Microsoft CVE Analysis

PortalFuse Quarterly Security Report

A comprehensive analysis of Microsoft Common Vulnerabilities and Exposures (CVEs) for Windows and Edge products, including severity ratings, attack vectors, and impact assessments.

Published: June 30, 2025 • For Period: April 2025 - June 2025

Table of Contents

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
    Conclusion

    Section 7

  8. 8
    Appendix

    Section 8

Executive Summary & Key Statistics

This quarter's analysis of 249 vulnerabilities affecting Windows and Microsoft Edge reveals a threat landscape defined by concentrated, high-impact risks that demand a strategic, proactive response from security leaders. While overall vulnerability volume has declined, over 64% of disclosures are high-severity. The data points to two clear and present dangers for the modern enterprise:

  1. Systemic Internal Risk: The dominant vulnerability category is Privilege Elevation (32.5%). This indicates that for any attacker who gains even a minor foothold, the pathways to full administrative control are numerous and well-defined, turning a small endpoint compromise into a potential network-wide incident.
  2. Critical Perimeter Risk: The most severe, remotely exploitable vulnerabilities are now concentrated in the web browser. As the primary client for identity and cloud services, a compromised browser represents a direct gateway to an organization's most sensitive data and applications, bypassing traditional network defenses.

While Microsoft's rapid patch deployment provides the necessary tools for remediation, it also creates a compressed timeline for response. To effectively mitigate these risks, security teams should prioritize the following strategic initiatives:

  • Focus on "Worst-Case" Scenarios: Nine specific vulnerabilities identified in this report can be exploited remotely with no user interaction. These represent the highest immediate risk and require priority remediation to neutralize the most direct threats.
  • Harden the Browser as an Identity Client: Given the browser's role as a critical identity gateway, a focused effort to enhance its security posture is essential. This includes deploying advanced security features and robust monitoring for all Intune-managed devices.
  • Shift from Reactive Patching to Proactive Hardening: Organizations must move beyond a purely reactive stance and proactively configure systems to block common attack techniques, particularly the memory safety flaws that underpin many of this quarter's most severe vulnerabilities.

This report provides the data-driven intelligence needed to act decisively. By focusing resources on these key areas, any organization can significantly strengthen its security posture and protect itself from the most pressing threats in the modern Microsoft environment.

Section 2

Quarterly CVE Landscape: Volume, Severity, and Categorization

Explore the quarter's Windows and Edge CVE landscape, from the volume of new and updated threats to their severity and categorization. Key metrics and charts reveal overall trends in vulnerability reporting and classification.

Quarterly CVE Landscape: Volume, Severity, and Categorization

Total CVEs
249
decrease 36.5%

Total vulnerabilities this quarter

Critical Count
1
decrease 88.9%

Number of 'Critical' rated CVEs

High Count
159
decrease 38.8%

Number of 'High' rated CVEs

% Critical & High CVEs
64.3 %
decrease 6.4%

Most problematic CVEs this quarter

The "Quarterly CVE Landscape" section provides a foundational, data-driven analysis of all Common Vulnerabilities and Exposures (CVEs) affecting Windows and Edge products disclosed between April 1 and June 30, 2025. Its objective is to quantify the total volume of vulnerabilities, their severity distribution, and their categorical breakdown. For system administrators and security leadership, these metrics offer a crucial baseline for gauging the scale of required vulnerability management efforts, identifying strategic trends, and allocating resources effectively against the most significant threats addressed by Microsoft this quarter.

During the reporting period, a total of 249 CVEs were analyzed. This volume represents a significant, albeit reduced, set of challenges for enterprise security teams. The subsequent analysis dissects this total, examining the monthly disclosure cadence, the severity profile of the vulnerabilities, and the specific types of threats they represent, establishing the essential context for the deeper technical assessments that follow in this report.

An analysis of the monthly disclosure trends, illustrated in Figure 1, reveals a heavily front-loaded quarter. Activity peaked in April with 93 new and 43 updated CVEs, marking it as the most volatile month. This initial surge was followed by a significant decline across May and June. By June, updated CVEs fell to just a single instance against 52 new entries. This pattern highlights a consistent influx of novel vulnerabilities and suggests that workloads for vulnerability triage and remediation were most intense at the start of the quarter.

Loading chart...
Figure 1. Trend of New vs. Updated Windows and Edge CVEs Published Monthly.
Chart Insight

New CVEs consistently outnumber updated CVEs across the quarter, with April recording the highest counts for both categories (93 new vs. 43 updated). Both new and updated counts decline over May (57 new vs. 3 updated) and June (52 new vs. 1 updated). The drop in updated CVEs is especially pronounced, falling from 43 in April to just a single update in June. This pattern indicates a narrowing gap in volume but a persistent dominance of new CVE entries each month.

The severity profile for this quarter, depicted in Figure 2, was unequivocally dominated by high-severity vulnerabilities. This classification far outpaced all others, peaking in April with 103 instances before declining to 31 in May and 25 in June. Medium-severity CVEs represented a consistent secondary factor, with counts of 28, 26, and 24 over the three months, indicating a steady stream of moderate-risk issues requiring attention.

Loading chart...
Figure 2. Monthly Windows and Edge CVE Volume by Assessed Severity.
Chart Insight

High-severity CVEs overwhelmingly dominated the quarter, peaking at 103 in April before declining to 31 in May and 25 in June. Medium-severity vulnerabilities were the second most common, with counts of 28 in April, 26 in May, and 24 in June. Critical CVEs were virtually absent, appearing only once in May, while low-severity issues only emerged with two instances in June. Overall, high-severity findings consistently outnumbered all other severity levels throughout the period.

In stark contrast to the prevalence of high-severity issues, critical-severity vulnerabilities were nearly nonexistent, with only a single case recorded in May. Low-severity vulnerabilities were similarly marginal, with only two instances appearing in June. Despite the scarcity of critical-level threats, the combined weight of critical and high-severity findings constituted 64.3% of all reported CVEs, reinforcing the strategic necessity of prioritizing response efforts on issues carrying the greatest potential impact.

The quarter's overall median CVSS score registered at 7.5, a figure that reinforces the predominance of vulnerabilities with meaningful risk profiles. While this is slightly lower than the preceding period, a median score in the 'High' severity range indicates that, on average, the vulnerabilities disclosed require timely and methodical remediation to mitigate substantial security risks.

Examining the specific nature of the threats, the landscape was primarily defined by three key categories. As detailed in Figure 3, these top-tier threats collectively account for over two-thirds of all reported issues, underscoring a concentrated adversary focus on specific attack vectors. The most prominent of these was Privilege Elevation, followed by Remote Code Execution and Information Disclosure.

Loading chart...
Figure 3. Distribution of Windows and Edge CVEs by Vulnerability Category for the Quarter.
Chart Insight

Privilege Elevation vulnerabilities dominate the quarter’s CVE portfolio, accounting for 81 entries or roughly one-third of all reported issues. Remote Code Execution (45 CVEs, 18%) and Information Disclosure (43 CVEs, 17%) are the next most common categories, together comprising over one-third of the total. Denial of Service (19 CVEs, 8%), Security Feature Bypass (17 CVEs, 7%), and Spoofing (14 CVEs, 6%) each represent substantially smaller portions. A negligible remainder (1%, 3 CVEs) lacked categorical assignment.

Privilege Elevation vulnerabilities emerged as the single largest category, with 81 CVEs representing 32.5%—nearly one-third—of all disclosures. This pronounced dominance signals a persistent and significant threat vector aimed at compromising privilege boundaries within enterprise environments. The sustained focus on exploiting authentication, authorization, and permission models highlights a critical area of ongoing risk for identity and endpoint security.

A quarter-over-quarter comparison reveals a significant contraction in both risk and volume. The total CVE count fell by 36.5% (143 fewer CVEs), and the combined share of high and critical-severity vulnerabilities decreased by 6.4 percentage points. The near-elimination of critical-severity issues—dropping from nine last quarter to just one—and the slight reduction in the median CVSS score from 7.8 to 7.5 suggest a modest easing of the overall risk profile for Windows and Edge deployments.

This quarter’s overwhelming dominance of Privilege Elevation vulnerabilities, representing nearly a third of all CVEs, signals a fundamental and persistent threat vector that transcends routine patching. This trend directly undermines core security pillars, from centralized identity frameworks like Microsoft Entra to the integrity of remote and operational endpoints. It serves as a critical reminder that perimeter defenses alone are insufficient. The data compels a strategic shift toward robust internal privilege management, continuous monitoring of escalation pathways, and proactive identity protection to effectively counter the risk of lateral movement and prevent widespread enterprise compromise.

The Q2 2025 CVE landscape is defined by a marked reduction in vulnerability volume and top-tier severity. However, high-severity issues remain the predominant challenge, with Privilege Elevation, Remote Code Execution, and Information Disclosure constituting the core of the threat profile. The data indicates that Windows 11 24h2 x64-based systems were the most frequently affected product segment, highlighting the need for focused attention on these platforms. This foundational analysis equips security teams with a precise, strategic understanding of the primary challenges and trends from the past quarter, setting the stage for the granular deep dives that follow.

Summary

This quarter's CVE landscape analysis reveals a significant, 36.5% reduction in overall vulnerability volume, with a total of 249 CVEs affecting Windows and Edge products. Despite this decline, the risk profile remains heavily weighted toward high-severity issues, which constituted 64.3% of all disclosures and contributed to a median CVSS score of 7.5. The data confirms that Privilege Elevation was the predominant threat category, accounting for nearly one-third of all vulnerabilities, which, combined with the scarcity of critical-severity CVEs, defines the quarter's primary security challenges.

In summary, while the decrease in CVE volume suggests a reduced attack surface, the sustained dominance of high-severity and privilege-based threats demands focused defensive strategies. The findings underscore a critical need to prioritize internal security controls, particularly robust identity and access management, to mitigate the risk of lateral movement and privilege abuse. This is especially crucial for the most affected platforms, such as Windows 11 24h2 x64-based systems. This analysis provides a clear benchmark for vulnerability triage and sets the stage for the deeper, product-specific examinations that follow.

Section 3

Attack Surface Analysis: Exploitability & Access

Analyze the evolving attack surface by examining vulnerability exploitability, including attack vectors, privilege requirements, user interaction, and overall complexity. Discover how these factors shape the risk profile and highlight common...

Attack Surface Analysis: Exploitability & Access

Network Vector
49.8 %
decrease 0.4%

% of Network Vector CVEs

Adjacent Vector
0.4 %
decrease 82.5%

% of Adjacent Network Vector CVEs

Local Vector
44.6 %
increase 15.7%

% of Local Vector CVEs

Physical Vector
0.8 %
decrease 90.2%

% of Physical Vector CVEs

The "Attack Surface Analysis: Exploitability & Access" section moves beyond theoretical severity to dissect the practical, real-world exploitability of this quarter's vulnerabilities. To truly understand operational risk, security teams must analyze the specific pathways an adversary could leverage. This analysis equips administrators to transition from a reactive to a proactive security posture by illuminating the most probable and impactful threats, distinguishing, for example, a network-based, no-privilege exploit from one requiring local access and user complicity.

To achieve this, our analysis interrogates four key dimensions of exploitability. This framework is designed to help technical leaders and engineers expertly prioritize remediation efforts by focusing on the characteristics that make a vulnerability most dangerous in a live environment. Understanding these factors is the key to moving beyond simple CVSS scores and toward a truly risk-informed security strategy.

Attack Vector: This dimension identifies the pathway through which a vulnerability can be exploited, such as the Network, Adjacent Network, Local, or Physical. A Network vector is typically the most critical, as it indicates a vulnerability can be attacked remotely over the internet, dramatically expanding the pool of potential attackers and requiring no prior access to the target's local environment.

Privileges Required: This metric specifies the level of system access an attacker must possess before they can exploit the vulnerability (None, Low, or High). Vulnerabilities requiring 'None' are exceptionally dangerous because they represent an unauthenticated attack surface, meaning an adversary needs no credentials or prior foothold to launch an attack.

User Interaction: This factor determines whether a legitimate user must take an action, such as clicking a link or opening a malicious file ('Required'), for the exploit to succeed. Vulnerabilities that require 'None' are of higher concern because they can often be automated and spread without human intervention, sometimes leading to wormable threats.

Attack Complexity: This dimension assesses the operational difficulty of an exploit, considering conditions beyond the attacker's control ('Low' or 'High'). A 'Low' complexity rating signifies that an attacker can expect repeatable success against any vulnerable target, indicating fewer hurdles and making the vulnerability ripe for widespread, opportunistic exploitation.

By examining these factors in combination, we can construct a nuanced, multi-dimensional view of risk. The following analysis will now proceed to apply this framework to the quarter's data, starting with the foundational distribution of attack vectors and building toward a synthesized, operational picture of the threat landscape.

Analysis of attack vectors, shown in Figure 4, reveals that the threat landscape is dominated by remote and local access pathways. Network-based vectors lead with 49.8% of all CVEs, followed closely by Local vectors at 44.6%. Together, these constitute over 94% of the total, indicating that the vast majority of vulnerabilities are accessible without physical proximity. The prevalence of Network vectors, in particular, signals broad exposure to remote exploitation, bypassing geographical or environmental constraints.

Loading chart...
Figure 4. Distribution of Attack Vectors for Windows and Edge CVEs.
Chart Insight

Network-based attack vectors account for 49.8% of CVEs, making it the most prevalent vector. Local attack vectors follow closely at 44.6%. Physical and adjacent vectors are markedly less common, representing 0.8% and 0.4% of CVEs respectively. Combined, network and local vectors constitute over 94% of the distribution, while physical and adjacent total under 2%.

Figure 5 deepens this analysis by cross-tabulating exploit pathways with the access an attacker must possess beforehand. A critical pattern emerges: the Network vector overwhelmingly pairs with "No Privileges," representing 103 out of 124 cases. This finding underscores a severe operational concern, as it confirms that most remotely exploitable vulnerabilities are accessible to unauthenticated attackers, dramatically amplifying their potential reach and impact.

Loading chart...
Figure 5. Breakdown of Attack Vectors by Privilege Requirements
for Windows and Edge CVEs.
Chart Insight

The Network attack vector accounts for the highest number of CVEs requiring no privileges (103 out of 124), with 20 low-privilege and a single high-privilege case. In contrast, the Local vector is dominated by low-privilege requirements (83 CVEs), supplemented by 22 no-privilege and six high-privilege cases. Adjacent and Physical vectors contribute only one and two no-privilege CVEs respectively, with no low- or high-privilege entries. Overall, exploits over Network largely require no initial privileges, whereas Local attacks predominantly rely on low-level privileges.

Conversely, vulnerabilities requiring a Local attack vector predominantly necessitate Low Privileges (83 cases), with a smaller subset needing no prior access (22 cases). While this implies an attacker must first gain a foothold on the system, the data also suggests that once this minimal access is achieved, a wide array of privilege escalation pathways becomes available, making initial compromise a critical pivot point for broader attacks.

Further granularity emerges when cross-referencing vulnerability categories with their exploitability prerequisites, as shown in Figure 6. Remote Code Execution (RCE) vulnerabilities are almost universally Network-based and require No Privileges (32 cases), presenting a formidable challenge for defenders. Similarly, Denial of Service CVEs cluster strongly in the Network/No Privileges quadrant (15 cases). This concentration highlights specific vulnerability types that expose perimeter systems to immediate, unauthenticated threats.

Loading chart...
Figure 6. Privilege Requirements for Attack Vectors within each Vulnerability Category for Windows and Edge CVEs.
Chart Insight

Privilege Elevation vulnerabilities are overwhelmingly exploited via the Local attack vector with Low Privileges, accounting for 59 instances—far exceeding any other vector or privilege requirement in that category. Remote Code Execution CVEs are almost entirely Network-based with No Privileges (32 occurrences, versus 8 with Low Privileges and zero with High). Denial of Service flaws also cluster in the Network/No Privileges combination (15 occurrences) with only two Local/No Privileges cases. Information Disclosure and Security Feature Bypass show more dispersion but similarly favor Network/No Privileges or Local/Low Privileges.

Figure 7 adds another layer of operational nuance by examining user interaction and attack complexity. Within the critical Privilege Elevation category, a majority of vulnerabilities (48 cases) are characterized by low complexity and require no user action, making them dangerously efficient once an attacker has local access. RCEs, in contrast, frequently depend on user interaction (27 cases), suggesting that phishing and social engineering remain key enablers for this attack class. Across all categories, low-complexity vulnerabilities vastly outnumber high-complexity ones, indicating that for most high-impact threats, the barriers to exploitation remain minimal.

Loading chart...
Figure 7. Attack Complexity by User Interaction within each Vulnerability Category for Windows and Edge CVEs.
Chart Insight

Privilege Elevation leads with 81 CVEs overall, driven predominantly by 48 low-complexity, no-user-action flaws. Remote Code Execution follows with 45 CVEs, skewed toward low-complexity exploits that require user interaction (27 vs. 3 without). Every category shows low-complexity counts far exceeding high-complexity ones, and only Remote Code Execution, Information Disclosure, Security Feature Bypass, and Spoofing register non-zero “user action required” CVEs. Denial of Service stands out with zero CVEs requiring user action and just 3 high-complexity cases, while Tampering has no recorded CVEs in any vector.

This quarter's attack surface is defined by two critical and distinct threat vectors. First, the predominance of low-complexity, no-privilege Network vulnerabilities exposes perimeter defenses like Microsoft Entra and Defender to immediate, unauthenticated compromise. Second, the high volume of Local privilege elevation vulnerabilities requiring only minimal user-level access creates a significant risk of post-compromise escalation. This dual threat demands a defense-in-depth strategy: while rigorous patching of the perimeter is essential, it must be complemented by stringent internal least-privilege enforcement and continuous monitoring to prevent any initial foothold from cascading into full administrative control.

Figure 8 synthesizes these dimensions into a unified operational risk model. Each point represents a CVE, plotted by a composite risk score, with bubble size and proximity to the center indicating higher CVSS scores. The chart reveals a dense clustering of vulnerabilities in the Low and Medium risk rings, with the 7.0–7.8 CVSS range being particularly populated. The High and Critical rings are sparse, but their occupants represent significant, high-impact threats, confirming a strong alignment between technical exploitability and assigned severity.

A crucial insight is provided by isolating the "worst-case" CVEs: those that are Network-based, require no privileges, demand no user interaction, and have low attack complexity. This quarter, nine such vulnerabilities were identified, a sharp increase from zero in the previous period. This nontrivial count signifies a distinct and elevated risk, as these CVEs expose organizations to immediate, remote, and potentially devastating attacks that require no user mistake or prior compromise.

Loading chart...
Figure 8. CVE Risk Chart. This chart displays CVEs based on a risk score and jittered within a risk ring for Windows and Edge CVEs.
Chart Insight

Figure 8 synthesizes all exploitability dimensions into a unified operational risk model, providing an at-a-glance prioritization tool. For an Intune administrator, the key is to understand how the risk rings are defined. The 'Low', 'Medium', and 'High' rings are primarily stratified by CVSS score, representing a traditional severity hierarchy.

However, the innermost 'Critical' ring is defined differently. A CVE is placed in this ring not just for a high CVSS score, but specifically if it meets all "worst-case" criteria: it is exploitable over the Network, requires No Privileges and No User Interaction, and has Low Attack Complexity. These are the most dangerous vulnerabilities for a managed device fleet, as they can be exploited remotely and automatically, without any user error, by an unauthenticated attacker. The presence of nine such vulnerabilities this quarter signals a significant and immediate threat that should be prioritized for patching above all others.

Simultaneously, the high concentration of local privilege elevation vulnerabilities that leverage minimal pre-existing access underscores an enduring threat vector for adversaries who achieve even a basic system foothold. For system engineers, the clear implication is that operational risk is overwhelmingly driven by the intersection of remote attack vectors and minimal access requirements. This necessitates a continuous reassessment of remediation priorities, focusing on the vulnerabilities that offer attackers the most direct and unimpeded path to compromise.

This quarter's attack surface is defined by a landscape where theoretical severity is matched by practical exploitability. The data reveals a persistent threat from low-complexity, no-privilege, network-exploitable vulnerabilities that dramatically expand an attacker's reach, particularly against perimeter systems like Microsoft Entra and Defender. This reality demands vigilant, risk-driven prioritization and a security posture that accounts for broad accessibility and ease of exploitation.

Summary

The "Attack Surface Analysis" provided a detailed examination of this quarter's operational threat landscape, moving beyond theoretical severity to focus on practical exploitability. The analysis confirmed that the attack surface is defined by two primary threat vectors. The first is a significant external exposure, with nearly half of all CVEs being exploitable over the network, often without requiring any prior privileges. The second is a potent internal threat, where a high volume of local vulnerabilities creates numerous pathways for privilege escalation once an attacker gains an initial foothold.

The external threat is underscored by the identification of nine "worst-case" CVEs—vulnerabilities that are network-based, require no privileges or user interaction, and have low complexity. This finding highlights a critical risk to perimeter systems, demanding rigorous patching and the stringent application of zero-trust principles. These vulnerabilities represent the most direct path to compromise and must be the highest priority for remediation to prevent unauthenticated, remote attacks.

Internally, the prevalence of local privilege escalation vulnerabilities signals an enduring risk from adversaries who achieve even minimal system access. This reality necessitates a robust defense-in-depth strategy that complements perimeter security with strong internal controls. The strategic imperative for security teams is to enforce least-privilege policies and enhance monitoring to detect and contain lateral movement, thereby mitigating the risk of a minor breach escalating into a full-blown compromise. This dual focus on both external and internal threats provides the necessary context for the deeper product and vulnerability analyses that follow.

Section 4

Deep Dive: CVSS Insights & Prioritization Hotspots

Gain deeper insights into CVSS scores and their distribution across vulnerability categories, identifying common weaknesses (CWEs) linked to high-risk Windows and Edge CVEs. Pinpoint prioritization hotspots by understanding the correlation...

Deep Dive: CVSS Insights & Prioritization Hotspots

In the "Deep Dive: CVSS Insights & Prioritization Hotspots" section, we shift our focus from the pathways of exploitation to the intrinsic severity and root causes of this quarter's vulnerabilities. While understanding the attack surface is crucial, a comprehensive risk assessment also requires dissecting the Common Vulnerability Scoring System (CVSS) scores and their distribution. A high average severity score can be misleading if it masks a wide variance; conversely, a category with a narrow range of consistently high scores signals a uniformly dangerous group of vulnerabilities.

Furthermore, this analysis drills down into the underlying software flaws by examining the most frequent Common Weakness Enumerations (CWEs). Identifying recurring CWEs is fundamental to proactive defense. It moves the focus from patching individual vulnerabilities to addressing systemic weaknesses in code and architecture, ultimately preventing future issues.

By exploring CVSS score distributions and spotlighting prevalent CWEs, this deep dive provides technical teams with the nuanced data needed for sharp risk prioritization and strategic defense planning.

This quarter’s review of CVSS base score distributions reveals that Remote Code Execution (RCE) vulnerabilities dominate both in terms of frequency and intrinsic severity. Figure 9, which presents the CVSS score distribution by category, uses a boxplot format to visually summarize these metrics for each major vulnerability class. In a boxplot, the central box captures the interquartile range (IQR)—the middle 50% of CVSS scores—while the line inside marks the median, and the whiskers extend to the minimum and maximum observed values. This enables a rapid assessment of both the central tendency and the degree of variability within each category.

Loading chart...
Figure 9. Box Plots of CVSS Scores per Category.
Chart Insight

Remote Code Execution vulnerabilities have the highest median CVSS base score (around 8.8), with the central 50 % of scores tightly clustered between approximately 7.8 and 8.8. Security Feature Bypass exhibits the greatest overall spread, ranging from about 5.4 up to 8.6. Information Disclosure shows a notable high-end outlier at 8.8, well above its upper quartile near 6.5.

Analysis of the RCE category demonstrates a distinctly severe and uniform risk profile. The median CVSS score for RCEs remains at a critical 8.8, with the bulk of scores closely clustered between approximately 7.8 and 8.8, reflecting a narrow IQR. This tightly bunched and high-scoring pattern indicates that nearly all RCE vulnerabilities this quarter are not only severe but also remarkably consistent in their potential impact—a finding reinforced by an overall 90th percentile (P90) CVSS of 8.8. Such uniformity minimizes ambiguity in prioritization: nearly every RCE identified represents an acute threat requiring heightened attention.

By contrast, other vulnerability categories display more variable risk profiles. Security Feature Bypass vulnerabilities, for instance, exhibit the widest spread in CVSS base scores, with values ranging from roughly 5.4 up to 8.6. This broad IQR signifies that while some feature bypass issues are of moderate concern, others reach high or even critical severity, necessitating detailed scrutiny on a case-by-case basis. Similarly, Information Disclosure vulnerabilities are generally of lower intrinsic severity (with most scores near 5.5–6.5), yet the presence of several high-end outliers—including those peaking at 8.8—signals sporadic, but significant, escalation risk within this category.

Turning to root causes, the quarter's CVE sample continues to demonstrate a marked concentration of high-severity flaws in a limited set of Common Weakness Enumerations (CWEs). Specifically, CWE-416 (Use After Free) and CWE-125 (Out-of-bounds Read) emerge as the most prevalent within high and critical CVEs, each with 34 documented instances. These two memory safety weaknesses collectively account for a substantially higher share of vulnerabilities than the third leading weakness, CWE-122 (Heap-based Buffer Overflow), which appears 28 times. The cumulative coverage of the top three CWEs reaches 59.6% this quarter—an increase of 11.3 percentage points (a 23.4% relative jump) compared to last quarter. This demonstrates a growing concentration of exploits leveraging a small set of systemic weaknesses, overwhelmingly in memory handling.

A more granular view is provided by Figure 10, which shows the CVSS distribution by attack vector for the top CWEs. Each panel of this visualization isolates a specific high-frequency CWE and presents the spread of severity (as measured by CVSS) depending upon the attack vector—most commonly, Network or Local. For instance, RCEs that exploit CWE-416 (Use After Free) over the network consistently present very high CVSS scores—predominantly at 8.8 and above—indicating robust exploitation potential regardless of implementation context. Local attack vector variants of CWE-416, while still severe (often scoring 7.8), exhibit slightly greater variability and do not consistently reach the critical threshold. This trend underscores the acute danger posed by remotely exploitable memory corruption bugs, cementing their place as top prioritization candidates for security operations.

Loading chart...
Figure 10. CVSS Distribution by Attack Vector for Top CWEs affecting Windows and Edge CVEs.
Chart Insight

CWE-416 (Use After Free) and CWE-125 (Out-of-bounds Read) are the most prevalent weaknesses in High and Critical CVEs, each appearing 34 times in the dataset. These two CWEs together account for a substantially larger share of vulnerabilities than the next most frequent, CWE-122 (Heap-based Buffer Overflow) with 28 occurrences. The remaining top CWEs—CWE-20 and CWE-591—are comparatively infrequent at 12 and 10 instances, respectively, indicating a strong concentration of high-risk issues in just the two leading categories.

Examining CWE-125 (Out-of-bounds Read), a similar but subtly distinct pattern arises. Network-exploitable variants show CVSS scores that swing from moderate (6.5) for pure disclosure scenarios, up to critical (8.8) where remote code execution or privilege escalation is feasible. Conversely, many local exposures of CWE-125 remain in the moderate-severity band (5.57.8), further accentuating the heightened risk that comes when these weaknesses are accessible over the network. This stratification, visible in the composite chart, exemplifies why both the type of flaw and its exploit context are essential for effective risk discrimination.

Beyond the top two, CWE-122 (Heap-based Buffer Overflow) displays consistently high CVSS scores—frequently reaching the 8.8 mark, especially when remotely exploitable. This echoes the broader pattern among memory safety defects: when these flaws can be exploited remotely, they represent some of the most damaging and repeatable threats in the Microsoft technology stack. The remaining top CWEs—such as CWE-20 (Improper Input Validation) and CWE-591 (Sensitive Data Storage in Improperly Protected Location)—are markedly less frequent and generally exhibit greater variance across attack vectors and severities, highlighting the outsized role of the primary three weaknesses.

In aggregate, memory safety remains the predominate systemic risk vector within Microsoft CVEs this quarter. Of all classified weaknesses, 120 are attributed to the memory safety category, with minimal representation from other classes such as improper access control or input validation/injection. Although the absolute count of memory safety bugs has declined since last quarter (down 31.0%), their relative contribution to critical and high-risk CVEs remains pronounced, as evinced by the top three CWEs’ expanded share.

Notably, no new CWE types emerged this quarter (new_cwe_types_this_qtr = 0), suggesting that adversaries and researchers continue to focus exploitation and discovery on well-worn, but insufficiently mitigated, categories of weakness—further reinforcing the persistent nature of memory management vulnerabilities in modern software architecture.

Synthesizing these findings, three insights crystallize for vulnerability management and defense prioritization within Microsoft environments:

  • Remote Code Execution vulnerabilities constitute an exceptionally consistent and severe risk area, as evidenced by their clustered high CVSS scores and tight IQR.
  • The overwhelming concentration of exploits in CWE-416, CWE-125, and CWE-122 points to entrenched, systemic memory safety challenges that serve as recurring footholds for sophisticated attacks, particularly when accessible via network vectors.
  • Although the total number of memory safety bugs fell this quarter, the intensification of CVEs within the highest-severity bands—and the rising coverage of the top CWEs—suggests adversaries continue to favor these proven paths of compromise, especially against foundational services critical for identity and endpoint security.

The quarter's data reveals a critical and predictable threat vector targeting the core of Microsoft's identity infrastructure. The predominance of high-severity Remote Code Execution (RCE) vulnerabilities, consistently clustered near CVSS 8.8 and driven by systemic memory safety flaws like CWE-416 (Use After Free), poses a direct risk to foundational services. Specifically, when these RCEs affect protocols like the Lightweight Directory Access Protocol (LDAP), they create an acute threat to the integrity of Entra ID. A successful exploit could allow an attacker to manipulate directory objects or bypass authentication controls, potentially leading to a full identity infrastructure compromise. This makes patching and monitoring network-facing services that handle authentication and directory queries the highest priority.

This depth of analysis refines the understanding of the Microsoft security landscape for the quarter. The combination of tightly clustered high CVSS scores in critical categories, and the persistent prevalence of particular memory-handling weaknesses, delineates clear prioritization hotspots. For technical and executive teams alike, the evidence underscores the acute and ongoing risk posed by remote, memory-based vulnerabilities—especially those mapped to well-known CWEs—in safeguarding the core of Microsoft's infrastructure and its identity-driven services.

Summary

This section's deep dive into vulnerability metrics provided a granular view of the quarter's risk landscape by analyzing both intrinsic severity and root causes. The examination of CVSS score distributions revealed a clear hierarchy of risk. Remote Code Execution (RCE) vulnerabilities stand out for their consistent and uniform severity, with a high median CVSS score and a narrow interquartile range, indicating that nearly every RCE is a critical threat. In contrast, other categories like Security Feature Bypass exhibit significant variability, demanding more nuanced, case-by-case risk assessment.

The analysis of root causes identified a profound concentration of risk within a few specific Common Weakness Enumerations (CWEs). Systemic memory safety issues, particularly CWE-416 (Use After Free), CWE-125 (Out-of-bounds Read), and CWE-122 (Heap-based Buffer Overflow), were the root cause of nearly 60% of high-severity vulnerabilities. The increasing dominance of these few CWEs quarter-over-quarter points to an entrenched and growing reliance by adversaries on a small set of well-understood, high-impact flaws.

Synthesizing these findings, it is clear that the most acute threats emerge where these two trends intersect: when systemic memory safety flaws manifest as network-exploitable RCEs. This convergence creates predictable and highly dangerous prioritization hotspots. For technical and executive teams, this analysis provides a clear mandate: focus defensive resources and strategic planning on mitigating these specific, recurring memory-based vulnerabilities to protect the core of Microsoft's infrastructure and its identity-driven services.

Section 5

Product Impact & Remediation Timeliness

Assess the impact of vulnerabilities on specific Windows and Edge products and the timeliness of remediation, highlighting the most affected software by CVE criticality. Understand patching and disclosure timelines through an analysis of NVD...

Product Impact & Remediation Timeliness

The "Product Impact & Remediation Timeliness" section shifts the analytical focus towards the tangible impact of vulnerabilities on specific Microsoft products and product families, and critically examines the timeliness of the remediation and disclosure lifecycle. Understanding which products are most frequently targeted or harbor the most severe vulnerabilities is essential for resource allocation in patching and system hardening. For instance, a high concentration of critical CVEs in widely deployed server products demands immediate attention from administrators.

Equally important is the timeliness aspect. The period between a vendor releasing a patch and the vulnerability details being publicly cataloged (e.g., in the National Vulnerability Database - NVD) represents a window of potential exposure where systems might be patched but full public awareness and standardized scoring are still pending. Conversely, delays in patching vulnerabilities that are already publicly known (or worse, exploited) increase risk. This section will analyze metrics such as the median days to NVD publication and the percentage of CVEs disclosed by NVD within critical timeframes post-vendor patch.

This analysis of product impact and disclosure/patching timeliness provides system administrators and security teams with actionable intelligence for prioritizing their efforts and understanding the dynamics of the vulnerability management ecosystem for Microsoft products.

A review of vulnerability distribution this quarter reveals a complex risk landscape across Microsoft’s product ecosystem. Significantly, Windows 11 24h2 x64-based systems exhibit the highest volume of reported CVEs, making it the most affected product for the period. The "Top Affected Products by CVE Criticality" chart (Figure 11) highlights a sustained concentration of high-severity vulnerabilities—95 entries for Windows 11 24h2 x64, closely followed by Windows 11 23h2 and 22h2 x64 editions, with 94 high-severity CVEs each. These figures represent a marked lead over all Windows 10 variants, which display notably lower high-severity counts, peaking at 72 for Windows 10 21h2 x64 and descending from there. Notably, no Windows edition registered any critical CVEs for the period under review.

Loading chart...
Figure 11. Products with Highest Counts of Critical/High CVEs for Windows and Edge.
Chart Insight

Microsoft Edge (Chromium) is the only product with a critical CVE (1), while none of the Windows editions report any critical vulnerabilities. High-severity CVE counts peak in Windows 11 x64 builds, with 95 in 24h2 and 94 each in 23h2 and 22h2. Windows 10 variants show lower high-severity counts ranging from 51 to 72 across editions and architectures. Medium/low severity CVEs follow a similar pattern, with the highest counts observed in the Windows 11 x64 releases.

This absence of critical vulnerabilities in the core Windows platform is a continuing trend from previous quarters. However, the persistent and high volume of high-severity CVEs in Windows 11 x64 releases points to an ongoing, nuanced threat to the operating system’s security posture. While catastrophic flaws are rare, the sustained prevalence of high-severity exploits poses a risk of gradual degradation in OS security baselines, potentially enabling advanced attack techniques such as privilege escalation or lateral movement. The continuous concentration of vulnerabilities within the latest Windows 11 builds underlines the expanding attack surface as these editions become central to critical enterprise workflows and identity platforms.

In sharp contrast, Microsoft Edge (Chromium) is the only product to register a critical-severity CVE during this quarter, as represented in the chart and supported by the data table (“1” in Critical column). Although its count of high-severity CVEs is lower than that of the leading Windows 11 builds (21 vs. 95+), the mere presence of any critical vulnerability in a client-facing application like Edge is significant. This highlights the shifting threat focus toward endpoint browsers, which now constitute key attack vectors—especially in environments where identity, web access, and physical endpoint boundaries increasingly intersect.

Analysis of remediation and public disclosure timelines indicates marked efficiency in the vendor-to-NVD publication pipeline. The median_days_to_patch statistic for the reporting period is exactly 0.0 days, reflecting that, for the majority of vulnerabilities, the NVD published details on the same day that patches became available. This lag time is unchanged from the previous quarter (as shown by a median_days_to_patch_qoq_delta_abs of 0.0), suggesting a stable trend. Such timeliness is further reinforced by the high rates of prompt publication: 96.3% of vulnerabilities are cataloged by NVD within seven days of patch release (patched_le_7d_pct), and this rises to 98.3% within thirty days (patched_le_30d_pct). Both of these rates show quarter-over-quarter improvements, with the seven-day metric rising by approximately 2.9% and the thirty-day metric increasing by 1.7%.

The "NVD Publication Delay by CVE Severity" chart (Figure 12) provides granularity into these trends by severity. For both Medium and High severity CVEs, the median delay to public disclosure remains at zero days, reflecting efficient processing and dissemination irrespective of risk level. However, the single Critical-severity CVE—affecting Microsoft Edge (Chromium)—exhibits a publication lag of four days. This isolated longer delay does not appear to represent a systemic gap but does highlight potential episodic risk for critical vulnerabilities in non-core products. Boxplot data indicates that while most publication intervals cluster around the release date, negative outliers occasionally arise, sometimes reflecting data artifacts or early reporting by external entities rather than actual early disclosure or exploitation scenarios.

Loading chart...
Figure 12. Days from Vendor Patch to NVD Publication, by Severity for Windows and Edge. Negative scores may indicate: 1) CVE revision after initial publication; 2) independent third-party NVD submissions prior to notifying Microsoft.
Chart Insight

The median delay to NVD publication is 0 days for both Medium and High severity CVEs, whereas the single Critical‐severity entry appears at 4 days. High‐severity CVEs display the greatest spread (from –3 to +4 days), Medium range is –2 to +4 days, and Critical shows no variability beyond its lone data point. Negative outliers in both Medium (down to –2 days) and High (down to –3 days) severities are consistent with expected data artifacts—either later CVE revisions by Microsoft or third‐party submissions to NVD preceding Microsoft’s publication.

Across both product and timeliness dimensions, there is no evidence this quarter of widespread “zero-day” exploitation—defined as vulnerabilities exploited prior to or concurrent with their NVD disclosure or patch release—within the available dataset. The absence of reported exploited CVEs (as inferred from the lack of any zero_day_count or similar metrics in this release) suggests that, for this quarter, vulnerability management teams did not face emergent threats from unpatched, in-the-wild exploits at the point of initial disclosure.

From a trend perspective, quarter-over-quarter analysis demonstrates a positive, if modest, improvement in disclosure velocity. Both seven- and thirty-day NVD publication percentages have increased compared to the prior period, reinforcing progress toward rapid normalization of CVE intelligence across the ecosystem. The median publication lag remains at zero, indicating consistent adherence to best practices in transparent and immediate communication of vulnerability details by Microsoft and downstream partners.

This quarter's data reveals a critical divergence in the Microsoft threat landscape. While the core Windows platform remains free of 'critical'-rated CVEs, the high and sustained volume of 'high'-severity vulnerabilities in the latest Windows 11 x64 editions signals a risk of gradual security erosion, creating pathways for sophisticated attacks like privilege escalation. Simultaneously, the quarter's sole 'critical' CVE appeared in Microsoft Edge, cementing the browser as the new frontier for the most severe, direct threats. This dual-risk profile demands a recalibrated defensive posture: administrators must manage the systemic risk within the OS through diligent patching while also prioritizing the browser as a primary vector for critical exploits.

Implications for administrators are clear from the pattern of impact. Given the abundance of high-severity CVEs in Windows 11 x64 environments, administrators should maintain heightened vigilance for rapid application of security patches to these systems, even in the absence of critical-rated vulnerabilities. While traditional anxieties might center on critical flaws, the sheer volume and complexity of high-severity vulnerabilities established in current Windows 11 builds present an equally pressing risk—potentially contributing to attack surface erosion in ways not immediately apparent through severity scoring alone. Administrators managing browser deployments, particularly Microsoft Edge, should also be aware of its elevated profile as a target, driven by the presence of both high- and critical-severity CVEs and reflecting evolving attack patterns.

The quarter’s data paints a nuanced but overall positive picture for remediation timeliness, marked by near-immediate public disclosure of most vulnerabilities and stable or improving trends compared to prior quarters. Product impact remains heavily skewed toward Windows 11 24h2 x64, which continues to see the highest volume of high-severity vulnerabilities, despite the absence of criticals. Meanwhile, critical CVEs have shifted toward the browser layer, specifically Microsoft Edge (Chromium), emphasizing the changing contours of operational risk for organizations dependent on Microsoft’s desktop and endpoint platforms. System administrators are thus presented with a landscape demanding rapid patching cadence, targeted vigilance toward new product releases, and a continued focus on endpoint and browser security in addition to traditional operating system hardening.

Summary

This section's analysis of product impact and remediation timelines revealed a distinct and evolving risk profile across the Microsoft ecosystem. The data confirms that the latest Windows 11 x64-based systems are the primary locus of vulnerabilities, characterized by a high volume of 'high'-severity CVEs. While no 'critical' flaws were found in the OS this quarter, this concentration of significant vulnerabilities points to a systemic risk that could erode established security baselines over time.

In a significant counterpoint, the quarter's sole 'critical'-rated CVE was found in Microsoft Edge (Chromium). This finding signals a clear shift in the threat landscape, where the most severe, single-point-of-failure risks are now emerging in client-facing applications rather than the core operating system. This elevates the browser's profile as a primary attack vector and a critical component of the endpoint security perimeter that demands heightened attention.

Despite this complex risk distribution, the vulnerability disclosure process remains remarkably efficient. A median NVD publication delay of zero days and consistently high rates of prompt cataloging demonstrate a mature and reliable intelligence pipeline. For security teams, this means the challenge is not a lack of timely information but rather the strategic application of it. The key takeaway is the need for a dual-focus defense: maintaining a rapid patching cadence for the systemic risk in Windows 11 while implementing enhanced hardening and monitoring for the acute, critical-level threats targeting the browser.

Section 6

Spotlight: This Quarter's Most Critical Vulnerabilities

Spotlight the quarter's most critical Windows vulnerabilities, offering detailed insights and CVSS scores for high-impact threats. Visualizations help uncover distinct patterns and shared characteristics among these significant issues, aiding in...

Spotlight: This Quarter's Most Critical Vulnerabilities

The "Spotlight: This Quarter's Most Critical Vulnerabilities" section provides a focused examination of a curated list of the most critical and potentially impactful Microsoft Windows vulnerabilities disclosed during this reporting period. While previous sections have analyzed broad trends and distributions, this spotlight aims to draw specific attention to individual CVEs that warrant heightened awareness due to their inherent severity, ease of exploitation, or observed activity in the threat landscape.

The goal here is not to be exhaustive, but rather to highlight exemplars of high-risk vulnerabilities. A key part of this analysis involves identifying what we term "Worst-Case Scenario CVEs"—vulnerabilities that possess a combination of characteristics making them exceptionally dangerous. By dissecting these specific cases, organizations can gain a more concrete understanding of the types of threats that demand immediate prioritization and can use these examples to test their own detection and response capabilities. This targeted analysis serves as a practical supplement to the broader statistical picture painted earlier in the report.

The vulnerabilities highlighted in this section are selected through a rigorous methodology that combines multiple risk factors. Primary selection criteria include a high Common Vulnerability Scoring System (CVSS) v3.1 base score, direct or credible evidence of exploitation, and exploitability features that indicate broad potential impact in Microsoft environments. Notably, to align the focus with risks most relevant to Windows-centric enterprises, the curation process excludes vulnerabilities rooted primarily in the open-source Chromium project—unless a given Chromium-based CVE manifests an atypical or heightened risk distinct within the Microsoft product landscape. Further, functionally duplicate CVEs occasionally published by Microsoft are typically consolidated; only a single representative is analyzed in-depth when product sub-versioning or minor contextual differences do not materially alter the impact profile. This approach sharpens the analysis on distinct threat types and streamlines attention to the most operationally significant CVEs within core Microsoft products.

Central to this spotlight is the "Worst-Case Scenario CVEs" metric. This refers to the subset of vulnerabilities that satisfy all of the following stringent CVSS vector criteria: an Attack Vector of Network (AV:N), Low Attack Complexity (AC:L), No Privileges Required (PR:N), and No User Interaction (UI:N). CVEs that meet all four conditions are especially dangerous, being both remotely exploitable and suitable for rapid, automated attacks without prerequisites or limitations. For this quarter, nine such "Worst-Case" CVEs were identified, representing a clear and immediate threat to corporate defenses by virtue of their exploitability and attack surface.

Loading chart...
Figure 13. CVSS scores of this quarter's most critical Windows and Edge CVEs.
Chart Insight

The CVSS base scores for the ten spotlight CVEs span a narrow range from 8.4 to 8.8. Eight of the ten vulnerabilities register at the maximum 8.8 score in this set, with one scoring 8.6 and one 8.4. All selected CVEs thus fall into the high-severity category, with a pronounced clustering at the top end of the CVSS scale.

For each selected CVE in this spotlight, the report presents core characteristics including its identifier, CVSS v3.1 base score, critical exploitability metrics, affected products, and a concise summary of the vulnerability’s potential operational impact. To establish an objective baseline for comparing the severity of these spotlighted risks, Figure 13 illustrates the CVSS base scores assigned to them. The scoring distribution for the ten highlighted vulnerabilities is notably narrow, spanning from 8.4 to 8.8, with eight of the ten registering the highest observed value in this subset (8.8). As such, all fall squarely within the high-severity category, with a marked clustering at the upper end—underscoring that the curated set consists exclusively of risks requiring elevated attention.

The following entries will now delve into the specifics of the high-priority vulnerabilities identified through the selection process described above.

Spotlight CVEs Summary Details

CVE-2025-21205 - Windows Telephony Service Remote Code Execution Vulnerability

A heap-based buffer overflow vulnerability in the Windows Telephony Service allows unauthorized attackers to execute arbitrary code over a network. This vulnerability is particularly concerning as it can be exploited remotely, requiring only that a user connects to a malicious server. While user interaction is necessary, the complexity is low, making it easier for attackers to succeed. The potential impact includes total loss of confidentiality, integrity, and availability. For remediation, administrators should ensure the following security updates are installed using standard enterprise patching tools:

  • Windows 10 Version 22H2 for x64-based Systems: KB5055518
  • Windows 11 Version 22H2 for x64-based Systems: KB5055528
  • Windows Server 2025: KB5055523

CVE-2025-26669 - Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

An out-of-bounds read vulnerability in Windows Routing and Remote Access Service (RRAS) could allow an unauthorized attacker to disclose sensitive information over a network. With a CVSS score of 8.8, this vulnerability poses a high risk. Attackers may exploit this by tricking users into sending requests to malicious servers, which could return harmful data leading to arbitrary code execution. Microsoft has released an official fix, and system administrators are advised to monitor for and apply the relevant security updates for all affected Windows versions, including Windows Server 2012, Windows Server 2008, and Windows 10.

CVE-2025-29840 - Windows Media Remote Code Execution Vulnerability

A stack-based buffer overflow vulnerability in Windows Media allows unauthorized remote code execution. This vulnerability (CVSS 8.8) can be exploited by an attacker convincing a user to open a specially crafted file, leading to arbitrary code execution in the context of the user. To mitigate this risk, administrators should deploy the following security updates:

  • Windows 10 Version 1607: KB5058383
  • Windows 10 Version 22H2: KB5058379
  • Windows Server 2022: KB5058385
  • Windows 11 Version 23H2: KB5058405

CVE-2025-29966 - Remote Desktop Client Remote Code Execution Vulnerability

A critical heap-based buffer overflow vulnerability (CVSS 8.8) in the Windows Remote Desktop Client allows unauthorized attackers to execute arbitrary code. This can be exploited when a victim connects to a compromised Remote Desktop Server using the vulnerable client. The attack does not require any prior privileges. System administrators are strongly advised to apply the relevant security updates to mitigate this risk:

  • Windows Server 2012 R2: KB5058403
  • Windows Server 2012: KB5058451
  • Windows Server 2008 R2: KB5058430
  • Windows 10 Version 22H2 / 21H2: KB5058379
  • Windows 11 Version 22H2: KB5058405
  • Windows Server 2016: KB5058383
  • Windows Server 2022: KB5058385
  • Remote Desktop client for Windows Desktop: KB5058392

CVE-2025-33053 - Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability

A remote code execution vulnerability (CVSS 8.8) exists in WebDAV due to external control of file names or paths. An attacker can exploit this over a network by tricking a user into clicking a specially crafted URL. The attack does not require any prior privileges, making it particularly dangerous. Microsoft has released an official fix, and system administrators are advised to apply the latest security patches to all supported versions of Microsoft Windows to mitigate this risk.

CVE-2025-33066 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

A heap-based buffer overflow vulnerability in Windows Routing and Remote Access Service (RRAS) allows unauthorized attackers to execute arbitrary code over a network. The attack vector is network-based, requiring user interaction to exploit, as the attacker must trick the user into connecting to a malicious server. This vulnerability is classified with a CVSS score of 8.8. Microsoft has released security updates, including KB5061018 for Windows Server 2012 R2, KB5061059 for Windows Server 2012, and KB5061078 for Windows Server 2008 R2, which should be deployed immediately.

CVE-2025-25000 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

A type confusion vulnerability in Microsoft Edge (Chromium-based) allows unauthorized attackers to execute code remotely. This vulnerability can be exploited by hosting a specially crafted website that targets Microsoft Edge. The potential impact includes high confidentiality, integrity, and availability risks. Microsoft has released an official fix, and system administrators are urged to ensure all clients are updated to version 135.0.3179.54 or later to mitigate the risk.

CVE-2025-33073 - Windows SMB Client Elevation of Privilege Vulnerability

A vulnerability in Windows SMB allows an authorized attacker to elevate privileges to SYSTEM level over a network. This issue arises from improper access control, enabling attackers with low privileges to exploit the vulnerability without requiring user interaction by convincing a victim to connect to a malicious SMB server. To mitigate this risk, administrators should:

  • Apply the relevant security updates for all affected systems, including Windows Server 2016, Windows 10, and Windows Server 2022.
  • Ensure that SMB signing is enabled to add an additional layer of security.
  • Regularly review and restrict access to SMB shares to minimize exposure.

CVE-2025-27737 - Windows Security Zone Mapping Security Feature Bypass Vulnerability

A vulnerability exists in Windows Security Zone Mapping due to improper input validation, allowing unauthorized attackers to bypass security features locally. An attacker with local access can exploit this by having a user execute a specially crafted URL. Successful exploitation could lead to privilege escalation. To mitigate the risk, administrators should deploy the following security updates:

  • Windows 10 Version 22H2 for x64-based Systems: KB5055518
  • Windows Server 2022: KB5055526
  • Windows 11 Version 23H2 for ARM64-based Systems: KB5055528

CVE-2025-26678 - Windows Defender Application Control Security Feature Bypass Vulnerability

A vulnerability in Windows Defender Application Control (WDAC) allows unauthorized attackers to bypass security features locally. This security feature bypass is due to improper access control, enabling attackers to execute unauthorized applications. The attack vector is local, requiring no special privileges or user interaction. To mitigate this risk, administrators should:

  • Ensure Windows Defender Application Control policies are correctly configured to restrict unauthorized applications.
  • Regularly update systems to the latest security patches to protect against known vulnerabilities.
  • Monitor system logs for any unauthorized access attempts or anomalies related to application execution.

To complement the detailed analysis of specific CVEs, we also explore broader patterns using a visualization technique called t-distributed Stochastic Neighbor Embedding (t-SNE). This method processes complex CVE data by projecting multi-faceted characteristics into a two-dimensional map. While t-SNE is not a conventional tool for daily system administration, its application here can help reveal inherent groupings or 'profiles' among diverse vulnerabilities. By observing how these CVEs cluster, we can potentially identify underlying similarities or distinctions in their nature that might otherwise be obscured in raw data, offering another perspective on threat trends.

Figure 14 presents this t-SNE projection as applied to the quarter’s vulnerability dataset. This visualization reveals clear structural differentiation among CVE profiles based on their core characteristics. Specifically, Elevation of Privilege (EoP) vulnerabilities with a local attack vector are tightly clustered in one area, while Chromium-based CVEs leveraging network attack vectors form a distinctly separated cluster. This clear separation confirms marked underlying differences—primarily in attack vector and category. No extreme outliers are present, implying that the reported vulnerabilities cluster into a limited set of meaningful operational profiles.

Loading chart...
Figure 14. t-SNE projection of Windows and Edge CVEs showing distinct vulnerability profiles.
Chart Insight

Figure 14 presents this t-SNE projection as applied to the quarter’s vulnerability dataset. The visualization reveals clear structural differentiation among CVE profiles based on their core characteristics. Specifically, Elevation of Privilege (EoP), Local Vector CVEs (blue) are tightly clustered in the positive region of the vertical axis (t-SNE Component 2), while Remote Code Execution (RCE), Network Vector CVEs (purple) form a distinct cluster in the negative region. This strong vertical separation indicates that, despite sharing some attributes along the horizontal axis (Component 1), their underlying profiles are fundamentally different, driven primarily by their category and attack vector. The absence of significant outliers suggests that the quarter's vulnerabilities fall into well-defined operational profiles.

This quarter's spotlight reveals two distinct and equally critical vulnerability profiles that demand a defense-in-depth strategy. First, the clear clustering of network-based Remote Code Execution (RCE) vulnerabilities, many requiring no privileges or user interaction, presents an immediate threat to the network perimeter and externally-facing services. This mandates prioritized patching and the reinforcement of network threat detection in Defender. Second, the dense cluster of local Elevation of Privilege (EoP) vulnerabilities underscores the significant risk of rapid escalation following any initial compromise. This necessitates robust internal monitoring and behavior analytics to detect and contain lateral movement before an attacker can reach critical identity components managed by Entra ID.

Table 7.1. Details of Spotlighted Windows Critical Vulnerabilities.
CVE IDPublishedCVSS ScoreTitleCWE ID
CVE-2025-212052025-04-088.80
Windows Telephony Service Remote Code Execution Vulnerability
CWE-122
CVE-2025-266692025-04-088.80
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CWE-125
CVE-2025-298402025-05-138.80
Windows Media Remote Code Execution Vulnerability
CWE-121
CVE-2025-299662025-05-138.80
Remote Desktop Client Remote Code Execution Vulnerability
CWE-122
CVE-2025-330532025-06-108.80
Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability
CWE-73
CVE-2025-330662025-06-108.80
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CWE-122
CVE-2025-250002025-04-038.80
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CWE-843
CVE-2025-330732025-06-108.80
Windows SMB Client Elevation of Privilege Vulnerability
CWE-284
CVE-2025-277372025-04-088.60
Windows Security Zone Mapping Security Feature Bypass Vulnerability
CWE-20
CVE-2025-266782025-04-088.40
Windows Defender Application Control Security Feature Bypass Vulnerability
CWE-284

Summary

This section provided a focused analysis of the quarter's most severe threats by spotlighting a curated list of "Worst-Case Scenario" vulnerabilities. The detailed examination confirmed that these CVEs, characterized by high CVSS scores, network exploitability, and low attack complexity, represent the upper echelon of operational risk. The consistent profile of these high-impact vulnerabilities, particularly those enabling remote code execution like the flaws in RRAS and the Remote Desktop Client, underscores an immediate and severe threat to enterprise environments that demands swift patching and heightened vigilance.

The analysis further revealed two distinct, high-risk vulnerability profiles through t-SNE visualization. The clear clustering of network-based Remote Code Execution (RCE) vulnerabilities highlights a persistent threat at the network perimeter, while a separate, dense cluster of local Elevation of Privilege (EoP) flaws points to a significant risk of post-compromise escalation. This dual-threat landscape illustrates a common attack chain: a remote breach followed by internal privilege escalation, requiring a multi-layered defensive strategy that addresses both vectors.

By dissecting these specific, high-impact examples, this spotlight provides a practical guide for security teams to prioritize remediation and test defensive postures against the most likely and dangerous attack patterns. The findings serve as a clear mandate to focus on both hardening externally-facing services and strengthening internal controls against lateral movement. This detailed examination of top-tier threats concludes our analysis of specific vulnerabilities, setting the stage for a broader discussion of strategic defense and mitigation in the final sections of the report.

Conclusion

This quarter's security landscape is not defined by a single, catastrophic vulnerability, but by a subtle and strategic evolution of the battlefield. The data tells a story of two fronts. The first is a war of attrition being waged within the Windows 11 operating system itself. Here, the absence of 'critical' CVEs is deceptive. Instead, adversaries are leveraging a high-volume, persistent barrage of 'high'-severity flaws, primarily systemic memory safety weaknesses like Use After Free. For an Intune administrator, this isn't about dodging a single silver bullet; it's about preventing the slow, methodical erosion of the OS security baseline, where each 'high'-severity flaw represents a potential foothold for privilege escalation or lateral movement that could bypass established controls.

The second front has opened on the perimeter, specifically within the browser. The emergence of the quarter's sole 'critical' CVE in Microsoft Edge is a tactical signal that cannot be ignored. It confirms that for direct, high-impact remote code execution, the browser is now the primary target. This is where the modern, identity-centric enterprise is most vulnerable. An exploit here doesn't just compromise a machine; it compromises a user's authenticated session, providing a gateway into the very heart of the corporate environment via Entra ID-federated services.

Strategic Imperatives for the Modern CISO

Therefore, the strategic imperative is one of adaptation. A defense-in-depth strategy is no longer a linear model of layered walls but a dynamic response to this two-front war.

  • Rebalance Endpoint Defense from OS-centric to Identity-centric: The fight has moved to the browser. Security teams must treat the browser not as an application, but as the primary identity client. This means prioritizing the deployment of advanced browser security features, enhancing monitoring for anomalous browser processes, and configuring Conditional Access policies that scrutinize the state of the browser itself as a condition for granting access to sensitive resources.
  • Shift from Reactive Patching to Proactive Hardening: Given the concentration of flaws in a few memory safety CWEs, a purely reactive, patch-based approach is a losing battle. The focus must shift to proactive hardening. For Intune fleets, this means aggressively enabling Attack Surface Reduction (ASR) rules that target common memory exploit techniques and leveraging Windows Defender Application Control (WDAC) to create a trusted execution environment, neutralizing entire classes of vulnerabilities before they can be exploited.
  • Weaponize Timeliness with Exploitability-Driven Prioritization: With a zero-day intelligence gap, the advantage goes to the swift. The "worst-case scenario" vulnerabilities identified in this report—network-based, no-privilege, no-interaction RCEs—are the adversary's preferred tools. Patching cycles must be explicitly driven by these exploitability metrics, not just by CVSS score. The goal is to remediate the most weaponizable flaws within hours, not days, collapsing the attacker's window of opportunity.

Ultimately, navigating this evolving threat landscape requires more than just vulnerability data; it demands strategic foresight. The two-front war—a battle of attrition against systemic OS weaknesses and a high-stakes defense of the identity perimeter—is the defining challenge for the modern Microsoft enterprise. At PortalFuse, our expertise is in decoding these complex signals and translating them into actionable, forward-looking security strategy. This report is a testament to our commitment to providing the clarity and deep insights necessary to not only defend today's environment but to anticipate and prepare for the threats of tomorrow. We are your partners in securing the cloud, the endpoint, and the identity that connects them.

Appendix

Table A1. CVEs Included in This Report (Windows-Specific)

CVE IDTitleCVE CategorySeverityCVSS ScorePublished
CVE-2025-33056CVE-2025-33056 Windows Local Security Authority (LSA) Denial of Service VulnerabilityDenial of Servicehigh7.52025-06-10
CVE-2025-32724CVE-2025-32724 Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityDenial of Servicehigh7.52025-06-10
CVE-2025-29971CVE-2025-29971 Web Threat Defense (WTD.sys) Denial of Service VulnerabilityDenial of Servicehigh7.52025-05-13
CVE-2025-26673CVE-2025-26673 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicehigh7.52025-05-13
CVE-2025-27473CVE-2025-27473 HTTP.sys Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-09
CVE-2025-27469CVE-2025-27469 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-09
CVE-2025-26673CVE-2025-26673 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-09
CVE-2025-26641CVE-2025-26641 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-09
CVE-2025-26641CVE-2025-26641 Microsoft Message Queuing (MSMQ) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-08
CVE-2025-27473CVE-2025-27473 HTTP.sys Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-08
CVE-2025-27469CVE-2025-27469 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-08
CVE-2025-26673CVE-2025-26673 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicehigh7.52025-04-08
CVE-2025-33057CVE-2025-33057 Windows Local Security Authority (LSA) Denial of Service VulnerabilityDenial of Servicemedium6.52025-06-10
CVE-2025-26651CVE-2025-26651 Windows Local Session Manager (LSM) Denial of Service VulnerabilityDenial of Servicemedium6.52025-04-08
CVE-2025-29955CVE-2025-29955 Windows Hyper-V Denial of Service VulnerabilityDenial of Servicemedium6.22025-05-13
CVE-2025-29957CVE-2025-29957 Windows Deployment Services Denial of Service VulnerabilityDenial of Servicemedium6.22025-05-13
CVE-2025-29954CVE-2025-29954 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service VulnerabilityDenial of Servicemedium5.92025-05-13
CVE-2025-27471CVE-2025-27471 Microsoft Streaming Service Denial of Service VulnerabilityDenial of Servicemedium5.92025-04-09
CVE-2025-27471CVE-2025-27471 Microsoft Streaming Service Denial of Service VulnerabilityDenial of Servicemedium5.92025-04-08
CVE-2025-26669CVE-2025-26669 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosurehigh8.82025-04-09
CVE-2025-26669CVE-2025-26669 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosurehigh8.82025-04-08
CVE-2025-29809CVE-2025-29809 Windows Kerberos Security Feature Bypass VulnerabilityInformation Disclosurehigh7.12025-04-09
CVE-2025-32715CVE-2025-32715 Remote Desktop Protocol Client Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-06-10
CVE-2025-29961CVE-2025-29961 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29960CVE-2025-29960 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29959CVE-2025-29959 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29958CVE-2025-29958 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29836CVE-2025-29836 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29835CVE-2025-29835 Windows Remote Access Connection Manager Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29832CVE-2025-29832 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-29830CVE-2025-29830 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-05-13
CVE-2025-27738CVE-2025-27738 Windows Resilient File System (ReFS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-09
CVE-2025-26672CVE-2025-26672 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-09
CVE-2025-21197CVE-2025-21197 Windows NTFS Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-09
CVE-2025-21197CVE-2025-21197 Windows NTFS Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-08
CVE-2025-27738CVE-2025-27738 Windows Resilient File System (ReFS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-08
CVE-2025-26672CVE-2025-26672 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosuremedium6.52025-04-08
CVE-2025-29974CVE-2025-29974 Windows Kernel Information Disclosure VulnerabilityInformation Disclosuremedium5.72025-05-13
CVE-2025-21336CVE-2025-21336 Windows Cryptographic Information Disclosure VulnerabilityInformation Disclosuremedium5.62025-04-02
CVE-2025-33065CVE-2025-33065 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33063CVE-2025-33063 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33062CVE-2025-33062 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33061CVE-2025-33061 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33060CVE-2025-33060 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33059CVE-2025-33059 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33058CVE-2025-33058 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33055CVE-2025-33055 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-33052CVE-2025-33052 Windows DWM Core Library Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-32722CVE-2025-32722 Windows Storage Port Driver Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-32720CVE-2025-32720 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-32719CVE-2025-32719 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-24069CVE-2025-24069 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-24068CVE-2025-24068 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-24065CVE-2025-24065 Windows Storage Management Provider Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-06-10
CVE-2025-29837CVE-2025-29837 Windows Installer Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-05-13
CVE-2025-29829CVE-2025-29829 Windows Trusted Runtime Interface Driver Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-05-13
CVE-2025-27742CVE-2025-27742 NTFS Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-04-09
CVE-2025-27742CVE-2025-27742 NTFS Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-04-08
CVE-2025-27736CVE-2025-27736 Windows Power Dependency Coordinator Information Disclosure VulnerabilityInformation Disclosuremedium5.52025-04-08
CVE-2025-29956CVE-2025-29956 Windows SMB Information Disclosure VulnerabilityInformation Disclosuremedium5.42025-05-13
CVE-2025-47969CVE-2025-47969 Windows Virtualization-Based Security (VBS) Information Disclosure VulnerabilityInformation Disclosuremedium4.42025-06-10
CVE-2025-29839CVE-2025-29839 Windows Multiple UNC Provider Driver Information Disclosure VulnerabilityInformation Disclosuremedium4.02025-05-13
CVE-2025-33073CVE-2025-33073 Windows SMB Client Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.82025-06-10
CVE-2025-3069Chromium: CVE-2025-3069 Inappropriate implementation in ExtensionsPrivilege Elevationhigh8.82025-04-03
CVE-2025-3068Chromium: CVE-2025-3068 Inappropriate implementation in IntentsPrivilege Elevationhigh8.82025-04-03
CVE-2025-3067Chromium: CVE-2025-3067 Inappropriate implementation in Custom TabsPrivilege Elevationhigh8.82025-04-03
CVE-2025-33067CVE-2025-33067 Windows Task Scheduler Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.42025-06-10
CVE-2025-33070CVE-2025-33070 Windows Netlogon Elevation of Privilege VulnerabilityPrivilege Elevationhigh8.12025-06-10
CVE-2025-33075CVE-2025-33075 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32718CVE-2025-32718 Windows SMB Client Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32716CVE-2025-32716 Windows Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32714CVE-2025-32714 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32713CVE-2025-32713 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32712CVE-2025-32712 Win32k Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-47955CVE-2025-47955 Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-06-10
CVE-2025-32709CVE-2025-32709 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-15
CVE-2025-29970CVE-2025-29970 Microsoft Brokering File System Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-32701CVE-2025-32701 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-30400CVE-2025-30400 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-30385CVE-2025-30385 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-32709CVE-2025-32709 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-32707CVE-2025-32707 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-32706CVE-2025-32706 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-24063CVE-2025-24063 Kernel Streaming Service Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-05-13
CVE-2025-27483CVE-2025-27483 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-29824CVE-2025-29824 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-27741CVE-2025-27741 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-27733CVE-2025-27733 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-27727CVE-2025-27727 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-26688CVE-2025-26688 Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-26679CVE-2025-26679 RPC Endpoint Mapper Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-26648CVE-2025-26648 Windows Kernel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-24073CVE-2025-24073 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-21204CVE-2025-21204 Windows Process Activation Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-09
CVE-2025-26639CVE-2025-26639 Windows USB Print Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-24062CVE-2025-24062 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-24058CVE-2025-24058 Windows DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-29812CVE-2025-29812 DirectX Graphics Kernel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-29811CVE-2025-29811 Windows Mobile Broadband Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27730CVE-2025-27730 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27728CVE-2025-27728 Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27490CVE-2025-27490 Windows Bluetooth Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27483CVE-2025-27483 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27476CVE-2025-27476 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27467CVE-2025-27467 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-26675CVE-2025-26675 Windows Subsystem for Linux Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-29824CVE-2025-29824 Windows Common Log File System Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-26648CVE-2025-26648 Windows Kernel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-24074CVE-2025-24074 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-24073CVE-2025-24073 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-24060CVE-2025-24060 Microsoft DWM Core Library Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-21204CVE-2025-21204 Windows Process Activation Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27741CVE-2025-27741 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27739CVE-2025-27739 Windows Kernel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27733CVE-2025-27733 NTFS Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27731CVE-2025-27731 Microsoft OpenSSH for Windows Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27727CVE-2025-27727 Windows Installer Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-26688CVE-2025-26688 Microsoft Virtual Hard Disk Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-26679CVE-2025-26679 RPC Endpoint Mapper Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.82025-04-08
CVE-2025-27484CVE-2025-27484 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-09
CVE-2025-26687CVE-2025-26687 Win32k Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-09
CVE-2025-29810CVE-2025-29810 Active Directory Domain Services Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-09
CVE-2025-29810CVE-2025-29810 Active Directory Domain Services Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-08
CVE-2025-27484CVE-2025-27484 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-08
CVE-2025-26687CVE-2025-26687 Win32k Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.52025-04-08
CVE-2025-29838CVE-2025-29838 Windows ExecutionContext Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.42025-05-13
CVE-2025-32721CVE-2025-32721 Windows Recovery Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.32025-06-10
CVE-2025-29841CVE-2025-29841 Universal Print Management Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-05-13
CVE-2025-27468CVE-2025-27468 Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-05-13
CVE-2025-27478CVE-2025-27478 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-09
CVE-2025-26665CVE-2025-26665 Windows upnphost.dll Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-09
CVE-2025-21191CVE-2025-21191 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-09
CVE-2025-26649CVE-2025-26649 Windows Secure Channel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-26640CVE-2025-26640 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-27492CVE-2025-27492 Windows Secure Channel Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-27475CVE-2025-27475 Windows Update Stack Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-26665CVE-2025-26665 Windows upnphost.dll Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-21191CVE-2025-21191 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-27732CVE-2025-27732 Windows Graphics Component Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-27478CVE-2025-27478 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh7.02025-04-08
CVE-2025-27488CVE-2025-27488 Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.72025-05-13
CVE-2025-26681CVE-2025-26681 Win32k Elevation of Privilege VulnerabilityPrivilege Elevationmedium6.72025-04-08
CVE-2025-3070Chromium: CVE-2025-3070 Insufficient validation of untrusted input in ExtensionsPrivilege Elevationmedium6.52025-04-03
CVE-2025-33053CVE-2025-33053 Internet Shortcut Files Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-06-19
CVE-2025-33066CVE-2025-33066 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-06-10
CVE-2025-33064CVE-2025-33064 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-06-10
CVE-2025-33053CVE-2025-33053 Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-06-10
CVE-2025-29967CVE-2025-29967 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-29966CVE-2025-29966 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-29964CVE-2025-29964 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-29963CVE-2025-29963 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-29962CVE-2025-29962 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-29840CVE-2025-29840 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-05-13
CVE-2025-25000CVE-2025-25000 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-18
CVE-2025-27481CVE-2025-27481 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-09
CVE-2025-27477CVE-2025-27477 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-09
CVE-2025-21222CVE-2025-21222 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-09
CVE-2025-21221CVE-2025-21221 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-09
CVE-2025-21205CVE-2025-21205 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-09
CVE-2025-21222CVE-2025-21222 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-08
CVE-2025-21221CVE-2025-21221 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-08
CVE-2025-21205CVE-2025-21205 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-08
CVE-2025-27481CVE-2025-27481 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-08
CVE-2025-27477CVE-2025-27477 Windows Telephony Service Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-08
CVE-2025-25000CVE-2025-25000 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh8.82025-04-03
CVE-2025-29828CVE-2025-29828 Windows Schannel Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-06-10
CVE-2025-26670CVE-2025-26670 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-04-09
CVE-2025-26663CVE-2025-26663 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-04-09
CVE-2025-26663CVE-2025-26663 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-04-08
CVE-2025-26670CVE-2025-26670 Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.12025-04-08
CVE-2025-27487CVE-2025-27487 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.02025-04-09
CVE-2025-27487CVE-2025-27487 Remote Desktop Client Remote Code Execution VulnerabilityRemote Code Executionhigh8.02025-04-08
CVE-2025-30388CVE-2025-30388 Windows Graphics Component Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-05-13
CVE-2025-27729CVE-2025-27729 Windows Shell Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-04-17
CVE-2025-27729CVE-2025-27729 Windows Shell Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-04-08
CVE-2025-26666CVE-2025-26666 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-04-08
CVE-2025-26674CVE-2025-26674 Windows Media Remote Code Execution VulnerabilityRemote Code Executionhigh7.82025-04-08
CVE-2025-29815CVE-2025-29815 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh7.62025-04-03
CVE-2025-30397CVE-2025-30397 Scripting Engine Memory Corruption VulnerabilityRemote Code Executionhigh7.52025-05-13
CVE-2025-29969CVE-2025-29969 MS-EVEN RPC Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-05-13
CVE-2025-29834Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-04-11
CVE-2025-26686CVE-2025-26686 Windows TCP/IP Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-04-09
CVE-2025-26668CVE-2025-26668 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-04-09
CVE-2025-26668CVE-2025-26668 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-04-08
CVE-2025-26686CVE-2025-26686 Windows TCP/IP Remote Code Execution VulnerabilityRemote Code Executionhigh7.52025-04-08
CVE-2025-29833CVE-2025-29833 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution VulnerabilityRemote Code Executionhigh7.12025-05-13
CVE-2025-27491CVE-2025-27491 Windows Hyper-V Remote Code Execution VulnerabilityRemote Code Executionhigh7.12025-04-09
CVE-2025-27491CVE-2025-27491 Windows Hyper-V Remote Code Execution VulnerabilityRemote Code Executionhigh7.12025-04-08
CVE-2025-27737CVE-2025-27737 Windows Security Zone Mapping Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh8.62025-04-09
CVE-2025-27737CVE-2025-27737 Windows Security Zone Mapping Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh8.62025-04-08
CVE-2025-26678CVE-2025-26678 Windows Defender Application Control Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh8.42025-04-08
CVE-2025-3052CVE-2025-3052 Cert CC: CVE-2025-3052 InsydeH2O Secure Boot BypassSecurity Feature Bypasshigh8.22025-06-10
CVE-2025-29842CVE-2025-29842 UrlMon Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.52025-05-13
CVE-2025-29809CVE-2025-29809 Windows Kerberos Security Feature Bypass VulnerabilitySecurity Feature Bypasshigh7.12025-04-08
CVE-2025-26637CVE-2025-26637 BitLocker Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.82025-04-09
CVE-2025-26637CVE-2025-26637 BitLocker Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.82025-04-08
CVE-2025-26635CVE-2025-26635 Windows Hello Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.52025-04-08
CVE-2024-28923CVE-2024-28923 Secure Boot Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.42025-06-13
CVE-2025-27735CVE-2025-27735 Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.02025-04-09
CVE-2025-27735CVE-2025-27735 Windows Virtualization-Based Security (VBS) Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium6.02025-04-08
CVE-2025-47160CVE-2025-47160 Windows Shortcut Files Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium5.42025-06-10
CVE-2025-27472CVE-2025-27472 Windows Mark of the Web Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium5.42025-04-09
CVE-2025-27472CVE-2025-27472 Windows Mark of the Web Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium5.42025-04-08
CVE-2025-33069CVE-2025-33069 Windows App Control for Business Security Feature Bypass VulnerabilitySecurity Feature Bypassmedium5.12025-06-10
CVE-2025-47182CVE-2025-47182 Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilitySecurity Feature BypassN/AN/A2025-06-26
CVE-2025-5066Chromium: CVE-2025-5066 Inappropriate implementation in MessagesSpoofingmedium6.52025-05-29
CVE-2025-5065Chromium: CVE-2025-5065 Inappropriate implementation in FileSystemAccess APISpoofingmedium6.52025-05-29
CVE-2025-29825Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofingmedium6.52025-05-01
CVE-2025-24054CVE-2025-24054 NTLM Hash Disclosure Spoofing VulnerabilitySpoofingmedium6.52025-04-25
CVE-2025-24071CVE-2025-24071 Microsoft Windows File Explorer Spoofing VulnerabilitySpoofingmedium6.52025-04-03
CVE-2025-5067Chromium: CVE-2025-5067 Inappropriate implementation in Tab StripSpoofingmedium5.42025-05-29
CVE-2025-26644CVE-2025-26644 Windows Hello Spoofing VulnerabilitySpoofingmedium5.12025-04-08
CVE-2025-29796CVE-2025-29796 Microsoft Edge for iOS Spoofing VulnerabilitySpoofingmedium4.72025-04-03
CVE-2025-25001CVE-2025-25001 Microsoft Edge for iOS Spoofing VulnerabilitySpoofingmedium4.32025-04-03
CVE-2025-47964CVE-2025-47964 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofinglowN/A2025-06-26
CVE-2025-47963CVE-2025-47963 Microsoft Edge (Chromium-based) Spoofing VulnerabilitySpoofinglowN/A2025-06-26
CVE-2025-3074Chromium: CVE-2025-3074 Inappropriate implementation in DownloadsSpoofingN/AN/A2025-04-03
CVE-2025-3073Chromium: CVE-2025-3073 Inappropriate implementation in AutofillSpoofingN/AN/A2025-04-03
CVE-2025-3072Chromium: CVE-2025-3072 Inappropriate implementation in Custom TabsSpoofingN/AN/A2025-04-03
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-06-10
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-05-13
ADV990001ADV990001 Latest Servicing Stack UpdatesUnknownN/AN/A2025-04-08
CVE-2025-4052Chromium: CVE-2025-4051 Insufficient data validation in DevToolschromium-basedcritical9.82025-05-01
CVE-2025-6192Chromium: CVE-2025-6192 Use after free in Profilerchromium-basedhigh8.82025-06-19
CVE-2025-6191Chromium: CVE-2025-6191 Integer overflow in V8chromium-basedhigh8.82025-06-19
CVE-2025-5959Chromium: CVE-2025-5959 Type Confusion in V8chromium-basedhigh8.82025-06-13
CVE-2025-5958Chromium: CVE-2025-5958 Use after free in Mediachromium-basedhigh8.82025-06-13
CVE-2025-5419Chromium: CVE-2025-5419 Out of bounds read and write in V8chromium-basedhigh8.82025-06-03
CVE-2025-5068Chromium: CVE-2025-5068 Use after free in Blinkchromium-basedhigh8.82025-06-03
CVE-2025-5063Chromium: CVE-2025-5063 Use after free in Compositingchromium-basedhigh8.82025-05-29
CVE-2025-5280Chromium: CVE-2025-5280 Out of bounds write in V8chromium-basedhigh8.82025-05-29
CVE-2025-47181CVE-2025-47181 Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerabilitychromium-basedhigh8.82025-05-22
CVE-2025-4372Chromium: CVE-2025-4372 Use after free in WebAudiochromium-basedhigh8.82025-05-08
CVE-2025-4050Chromium: CVE-2025-4096 Heap buffer overflow in HTMLchromium-basedhigh8.82025-05-01
CVE-2025-4096Chromium: CVE-2025-4052 Inappropriate implementation in DevToolschromium-basedhigh8.82025-05-01
CVE-2025-3620Chromium: CVE-2025-3620 Use after free in USBchromium-basedhigh8.82025-04-17
CVE-2025-3619Chromium: CVE-2025-3619 Heap buffer overflow in Codecschromium-basedhigh8.82025-04-17
CVE-2025-3066Chromium: CVE-2025-3066 Use after free in Navigationschromium-basedhigh8.82025-04-03
CVE-2025-29806CVE-2025-29806 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerabilitychromium-basedmedium6.52025-04-02
CVE-2025-4051Chromium: CVE-2025-4050 Out of bounds memory access in DevToolschromium-basedmedium6.32025-05-01
CVE-2025-6557Chromium: CVE-2025-6557 Insufficient data validation in DevToolschromium-basedmedium5.42025-06-26
CVE-2025-6556Chromium: CVE-2025-6556 Insufficient policy enforcement in Loaderchromium-basedmedium5.42025-06-26
CVE-2025-6555Chromium: CVE-2025-6555 Use after free in Animationchromium-basedmedium5.42025-06-26
CVE-2025-5283Chromium: CVE-2025-5283 Use after free in libvpxchromium-basedmedium5.42025-05-29
CVE-2025-5281Chromium: CVE-2025-5281 Inappropriate implementation in BFCachechromium-basedmedium5.42025-05-29
CVE-2025-5064Chromium: CVE-2025-5064 Inappropriate implementation in Background Fetch APIchromium-basedmedium5.42025-05-29
CVE-2025-4664Chromium: CVE-2025-4664 Insufficient policy enforcement in Loaderchromium-basedmedium4.32025-05-15
CVE-2025-4609Chromium: CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojochromium-basedN/AN/A2025-05-15
CVE-2025-3071Chromium: CVE-2025-3071 Inappropriate implementation in Navigationschromium-basedN/AN/A2025-04-03

Table A2. CVEs with CVSS scores that are outliers compared to their vulnerability category.

Outlier TypeCVSS ScoreCVE IDTitleCVE CategorySeverityPublished
High Outlier8.8CVE-2025-26669CVE-2025-26669 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosurehigh2025-04-09
High Outlier8.8CVE-2025-26669CVE-2025-26669 Windows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityInformation Disclosurehigh2025-04-08
High Outlier8.8CVE-2025-33073CVE-2025-33073 Windows SMB Client Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-06-10
High Outlier8.8CVE-2025-3069Chromium: CVE-2025-3069 Inappropriate implementation in ExtensionsPrivilege Elevationhigh2025-04-03
High Outlier8.8CVE-2025-3068Chromium: CVE-2025-3068 Inappropriate implementation in IntentsPrivilege Elevationhigh2025-04-03
High Outlier8.8CVE-2025-3067Chromium: CVE-2025-3067 Inappropriate implementation in Custom TabsPrivilege Elevationhigh2025-04-03
High Outlier8.4CVE-2025-33067CVE-2025-33067 Windows Task Scheduler Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-06-10
Low Outlier7.0CVE-2025-29841CVE-2025-29841 Universal Print Management Service Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-05-13
Low Outlier7.0CVE-2025-27468CVE-2025-27468 Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-05-13
Low Outlier7.0CVE-2025-27478CVE-2025-27478 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-09
Low Outlier7.0CVE-2025-26665CVE-2025-26665 Windows upnphost.dll Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-09
Low Outlier7.0CVE-2025-21191CVE-2025-21191 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-09
Low Outlier7.0CVE-2025-26649CVE-2025-26649 Windows Secure Channel Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-26640CVE-2025-26640 Windows Digital Media Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-27492CVE-2025-27492 Windows Secure Channel Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-27475CVE-2025-27475 Windows Update Stack Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-26665CVE-2025-26665 Windows upnphost.dll Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-21191CVE-2025-21191 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-27732CVE-2025-27732 Windows Graphics Component Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier7.0CVE-2025-27478CVE-2025-27478 Windows Local Security Authority (LSA) Elevation of Privilege VulnerabilityPrivilege Elevationhigh2025-04-08
Low Outlier6.7CVE-2025-27488CVE-2025-27488 Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege VulnerabilityPrivilege Elevationmedium2025-05-13
Low Outlier6.7CVE-2025-26681CVE-2025-26681 Win32k Elevation of Privilege VulnerabilityPrivilege Elevationmedium2025-04-08
Low Outlier6.5CVE-2025-3070Chromium: CVE-2025-3070 Insufficient validation of untrusted input in ExtensionsPrivilege Elevationmedium2025-04-03

Table A3. All Calculated Metrics

#Metric NameValue
1Total CVEs249
2Critical Count1
3High Count159
4Medium Count78
5Low Count2
6% Critical & High CVEs64.26
7High-to-Total Ratio63.86
8Most Volatile Month2025-04
9Median CVSS7.5
10P90 CVSS8.8
11Highest CVSS9.8
12Lowest CVSS4.0
13CVSS IQR1.3
14CVSS Score Variability1.17
15Average CVSS Score7.28
16CVSS Range by Category: Chromium-Based
  • Q1: 5.4
  • Median: 8.8
  • Q3: 8.8
  • IQR: 3.4
  • Lower_Fence: 0.3
  • Upper_Fence: 13.9
  • Count: 25
  • Mean: 7.65
  • StdDev: 1.7
17CVSS Range by Category: Denial Of Service
  • Q1: 6.35
  • Median: 7.5
  • Q3: 7.5
  • IQR: 1.15
  • Lower_Fence: 4.62
  • Upper_Fence: 9.23
  • Count: 19
  • Mean: 7.01
  • StdDev: 0.68
18CVSS Range by Category: Disclosure
  • Q1: 5.5
  • Median: 5.5
  • Q3: 6.5
  • IQR: 1.0
  • Lower_Fence: 4.0
  • Upper_Fence: 8.0
  • Count: 43
  • Mean: 5.98
  • StdDev: 0.88
19CVSS Range by Category: Feature Bypass
  • Q1: 5.85
  • Median: 6.65
  • Q3: 7.67
  • IQR: 1.83
  • Lower_Fence: 3.11
  • Upper_Fence: 10.41
  • Count: 16
  • Mean: 6.76
  • StdDev: 1.21
20CVSS Range by Category: Privilege Elevation
  • Q1: 7.5
  • Median: 7.8
  • Q3: 7.8
  • IQR: 0.3
  • Lower_Fence: 7.05
  • Upper_Fence: 8.25
  • Count: 81
  • Mean: 7.66
  • StdDev: 0.45
21CVSS Range by Category: Remote Code Execution
  • Q1: 7.8
  • Median: 8.1
  • Q3: 8.8
  • IQR: 1.0
  • Lower_Fence: 6.3
  • Upper_Fence: 10.3
  • Count: 45
  • Mean: 8.23
  • StdDev: 0.61
22CVSS Range by Category: Spoofing
  • Q1: 5.1
  • Median: 6.5
  • Q3: 6.5
  • IQR: 1.4
  • Lower_Fence: 3.0
  • Upper_Fence: 8.6
  • Count: 9
  • Mean: 5.78
  • StdDev: 0.91
23Cve Category Distribution Raw Counts
  • privilege_elevation: 81
  • remote_code_execution: 45
  • disclosure: 43
  • chromium-based: 27
  • denial_of_service: 19
  • feature_bypass: 17
  • spoofing: 14
  • none: 3
24% of RCE CVEs18.07
25% of EOP CVEs32.53
26% of DoS CVEs7.63
27% of Disclosure CVEs17.27
28% of Spoofing CVEs5.62
29% of Tampering CVEs0.0
30% of Feature Bypass CVEs6.83
31Top Vulnerability Categoryprivilege_elevation
32CVE Vulnerability Distributions: Privilege Elevation
  • count: 81
  • percentage: 32.53
33CVE Vulnerability Distributions: Remote Code Execution
  • count: 45
  • percentage: 18.07
34CVE Vulnerability Distributions: Disclosure
  • count: 43
  • percentage: 17.27
35CVE Vulnerability Distributions: Chromium-Based
  • count: 27
  • percentage: 10.84
36CVE Vulnerability Distributions: Denial Of Service
  • count: 19
  • percentage: 7.63
37CVE Vulnerability Distributions: Feature Bypass
  • count: 17
  • percentage: 6.83
38CVE Vulnerability Distributions: Spoofing
  • count: 14
  • percentage: 5.62
39CVE Vulnerability Distributions: None
  • count: 3
  • percentage: 1.2
40Network Vector49.8
41Local Vector44.58
42Adjacent Vector0.4
43Physical Vector0.8
44No User Action58.23
45User Action Required41.77
46No Privs Required Pct55.82
47Low Privileges Required41.37
48High Privileges Required2.81
49Low Attack Complexity77.51
50High Attack Complexity18.07
51High Risk Cves
    • cve_id: CVE-2025-4052
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-4052
    • title: Chromium: CVE-2025-4051 Insufficient data validation in DevTools
    • cvss: 9.8
    • cvss: 7.5
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26641
    • cve_id: CVE-2025-26641
    • title: CVE-2025-26641 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
    • cvss: 7.5
    • cve_id: CVE-2025-27469
    • title: CVE-2025-27469 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27469
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-3070
    • cvss: 6.5
    • title: Chromium: CVE-2025-3070 Insufficient validation of untrusted input in Extensions
    • cve_id: CVE-2025-3070
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26673
    • title: CVE-2025-26673 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
    • cvss: 7.5
    • cve_id: CVE-2025-26673
    • cve_id: CVE-2025-29971
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29971
    • title: CVE-2025-29971 Web Threat Defense (WTD.sys) Denial of Service Vulnerability
    • cvss: 7.5
    • cvss: 7.5
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32724
    • title: CVE-2025-32724 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
    • cve_id: CVE-2025-32724
    • title: CVE-2025-27473 HTTP.sys Denial of Service Vulnerability
    • cvss: 7.5
    • cve_id: CVE-2025-27473
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27473
    • source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33056
    • cvss: 7.5
    • title: CVE-2025-33056 Windows Local Security Authority (LSA) Denial of Service Vulnerability
    • cve_id: CVE-2025-33056
52High Risk CVEs9
53Exploited Count KevN/A
54Exploited Pct KevN/A
55Top 3 Affected Builds
Build #1
  • Build Version: 10.0.22621.5191
  • Count: 69
Build #2
  • Build Version: 10.0.26100.3775
  • Count: 69
Build #3
  • Build Version: 10.0.22631.5191
  • Count: 69
56Cwe Category Distribution
  • memory_safety: 120
  • race_concurrency: 3
  • improper_access_control: 12
  • input_validation_injection: 16
  • cryptographic_issues: 0
  • configuration_weakness: 0
  • logic_state_errors: 0
  • none: 102
57Top Common WeaknessCWE-416
58Top 3 CWEs Coverage59.6
59Memory Safety Bugs120
60Logic State Errors0
61Race Concurrency Count3
62Improper Access Control Count12
63Input Validation Injection Count16
64Cryptographic Issues Count0
65Configuration Weakness Count0
66Memory Safety vs Logic BugsInf:1 (No Logic)
67Count of newly seen CWEs0
68Typical Patch Delay0.0
69Patched within 7 days96.28
70Patched within 30 days98.35
71Exploited Before PatchedN/A
72Most Affected Product(s)Windows 11 24h2 x64-based systems
73Percentage of missing key data2.88
74Total CVE Records Processed249
75Spotlight Cwe Slot 1
  • cwe_id_raw: CWE-838
  • display_cwe_label: CWE-838: Unknown CWE Name
  • count: 1
  • avg_cvss: 9.8
  • predominant_category_raw: chromium-based
  • display_predominant_category: Chromium-Based

A. Data Collection Methodology

The data used to generate this report was collected from the National Vulnerability Database (NVD) and the Microsoft Security Response Center (MSRC).

The NVD is a repository of information about vulnerabilities in software products. It is a collaborative effort between the U.S. government and the private sector to provide a single source of information about vulnerabilities in software products.

Information regarding Common Weakness Enumeration (CWE) identifiers associated with CVEs is primarily drawn from data provided by the National Vulnerability Database (NVD). For detailed definitions, descriptions, and hierarchical categorizations of these CWEs, this report refers to the official MITRE CWE™ list and classifications available at cwe.mitre.org.

B. Statistics Notes

Several assumptions were used in order to complete the calculations of various metrics presented in this report.

For example, the CVSS score of a CVE is calculated based on the CVSS v3.1 formula, which takes into account the base score, temporal score, and environmental score. The base score is calculated based on the severity of the vulnerability, the attack vector, the attack complexity, the privileges required, the user interaction required, and the scope of the vulnerability. The temporal score is calculated based on the confidentiality, integrity, and availability impact of the vulnerability. The environmental score is calculated based on the confidentiality, integrity, and availability impact of the vulnerability, as well as the attack vector, the attack complexity, the privileges required, the user interaction required, and the scope of the vulnerability.

The metric "Worst Case CVEs" was based on a weighted average with the following properties:

This classification model is designed to isolate vulnerabilities that represent a 'worst-case scenario' by applying a strict set of criteria based on their CVSS vector string. Rather than calculating a continuous risk score, this method uses a binary filter to identify a specific profile of maximum exploitability and operational risk. A vulnerability is categorized as a worst-case scenario if and only if it meets all four of the conditions outlined below.

Worst-Case Scenario Criteria:
  1. The vulnerability is remotely exploitable over a network.
  2. The attack complexity is low, requiring no special conditions.
  3. The attacker requires no prior privileges on the target system.
  4. The exploit requires no interaction from a user.
Logical Formulation (LaTeX Notation):

Boolean Condition:

C_{wc} = (AV=N) \land (AC=L) \land (PR=N) \land (UI=N)

Set Theory Notation:

V \in \text{WorstCase} \iff C_{wc}(V) = \text{True}

Where:

  • Cwc represents the logical conjunction (AND operation) of the four worst-case conditions.
  • Each component of the CVSS vector must match a specific value:
    • Attack Vector (AV) must be 'Network' (N).
    • Attack Complexity (AC) must be 'Low' (L).
    • Privileges Required (PR) must be 'None' (N).
    • User Interaction (UI) must be 'None' (N).
  • A vulnerability V is classified as Worst-Case if and only if the condition Cwc evaluates to True.

This binary classification approach provides an unambiguous method for prioritizing threats that pose the most immediate and severe risk to the enterprise perimeter.

Understanding Boxplots and Outlier Detection

Boxplots (or box-and-whisker plots) are graphical representations that display the distribution of a dataset based on a five-number summary: minimum, first quartile (Q1), median (Q2), third quartile (Q3), and maximum. They provide a concise visual summary of key statistical measures presented in this report.

  • The central "box" spans the Interquartile Range (IQR), which is the range between the first quartile (Q1, representing the 25th percentile) and the third quartile (Q3, representing the 75th percentile). This box contains the middle 50% of the data.
  • A line within the box marks the median (Q2, or 50th percentile) of the dataset.
  • "Whiskers" extend from the ends of the box. In this report, they indicate the range of data within 1.5 times the IQR beyond the first and third quartiles.

For identifying potential outliers, the following standard statistical method, often referred to as Tukey's fences, is employed:

  • The Interquartile Range (IQR) is calculated as: IQR = Q3 - Q1.
  • The Lower Fence (or inner fence) is established at: LF = Q1 - (1.5 * IQR).
  • The Upper Fence (or inner fence) is established at: UF = Q3 + (1.5 * IQR).

Data points that fall below the Lower Fence or above the Upper Fence are considered potential outliers and are typically plotted as individual points beyond the whiskers. The whiskers themselves then extend to the minimum and maximum data values that lie within these calculated fences (i.e., the smallest data point greater than or equal to LF, and the largest data point less than or equal to UF).

Data Selection from Multiple NVD Signing Authorities

A single Common Vulnerabilities and Exposures (CVE) entry within the National Vulnerability Database (NVD) can sometimes include multiple sets of Common Vulnerability Scoring System (CVSS) data. This occurs when different organizations (signing authorities, such as NVD itself, software vendors like Microsoft, or other CNA - CVE Numbering Authorities) provide their own assessment of a vulnerability.

For consistency and to ensure a conservative (worst-case) perspective in this report, when multiple CVSS scores are present for a single CVE, the highest available CVSS Base Score is selected for all analyses and metric calculations. The full vector string associated with this highest score is also adopted.

Example:

Consider a hypothetical CVE, CVE-2024-ABCDE, with the following CVSS data provided by different authorities:

  • NVD (NIST) Assessment: CVSS Base Score 7.8 (Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
  • Vendor X Assessment: CVSS Base Score 8.1 (Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
  • Vendor Y Assessment: CVSS Base Score 7.5 (Vector: AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

In this scenario, the data used for this report would be from Vendor X: a CVSS Base Score of 8.1 and its corresponding vector string, as this represents the highest severity assessment among the available sources.

Patch Delay Calculation and Assumptions

The "Patch Delay" metric presented in this report quantifies the time elapsed between Microsoft's initial public disclosure of a CVE and its subsequent publication in the National Vulnerability Database (NVD). It is calculated as:

Patch Delay = NVD Published Date - Microsoft CVE Published Date

The calculation relies on the following key assumptions regarding the date fields used:

  • Microsoft CVE Published Date: This is sourced from the publishedDate field in Microsoft's Security Update Guide (SUG) or MSRC API data. It is assumed to represent the date Microsoft formally announced or publicly disclosed the vulnerability.
  • NVD Published Date: This refers to the publishedDate field associated with the CVE entry in the NVD. It is assumed to approximate the date when a patch or mitigation was officially documented and made widely available, often aligning with the NVD's own publication timeline after receiving and processing the CVE information.

It is important to acknowledge that this method provides an empirical estimate of patch delay. The dates used are proxies and may not always perfectly correspond to the precise moment of initial vulnerability announcement versus actual patch availability. Factors such as coordination between vendors and NVD, processing times, and differing definitions of "published" can introduce variability. Therefore, while practical for trend analysis, this metric rests on an interpretative foundation regarding the significance of these specific date fields.

CWE Grouping for Thematic Analysis

To facilitate a higher-level understanding of prevalent vulnerability types, individual Common Weakness Enumeration (CWE) identifiers are mapped to broader, feature-engineered root cause categories. This thematic grouping helps in identifying trends and patterns in the types of software weaknesses exploited. These categories are defined within the project's analytical framework and include:

  • Memory Safety: Encompasses vulnerabilities related to how software manages computer memory, such as buffer overflows, use-after-free, and null pointer dereferences. These can lead to crashes, arbitrary code execution, or information disclosure.
  • Input Validation and Injection: Covers weaknesses where software does not properly validate, sanitize, or neutralize input from users or external sources. This includes SQL injection, Cross-Site Scripting (XSS), command injection, and path traversal.
  • Improper Access Control: Relates to failures in enforcing permissions and privileges, allowing unauthorized actors to access or modify resources, or escalate their privileges. Examples include missing authorization checks or insecure direct object references.
  • Race Conditions and Concurrency: Arises from incorrect handling of sequences or timing of operations in multi-threaded or distributed environments, potentially leading to data corruption, deadlocks, or exploitation of time-of-check to time-of-use (TOCTOU) flaws.
  • Cryptographic Issues: Includes problems with the use of cryptographic algorithms, such as weak ciphers, improper key management, or missing encryption for sensitive data, potentially exposing information or compromising system integrity.
  • Configuration Weaknesses: Stems from insecure default settings, misconfigurations of software or systems, or overly permissive configurations that can be exploited by attackers.
  • Logic and State Errors: Pertains to flaws in the design or implementation of business logic or state management within an application, leading to unexpected behavior that can be leveraged for malicious purposes.

This categorization aids in strategic discussions about mitigation efforts and common pitfalls in software development.